216.73.216.6

A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups

· Published 26/01/2026 20:30 · Modified 27/01/2026 07:34

Export JSON

Essential information

Published
26/01/2026 20:30
Modified
27/01/2026 07:34
Tags
2026-01-26 CVE-2020-16040 apt biopass rat c&c framework china-aligned darknimbus gambling government grayrabbit holodonut jscript lolbins mkdoor peckbirdy wizardnet
Related entities
1 vulnerabilities (cve), 21 observables, 1 intrusion sets (apt), 19 techniques (mitre), 7 malware, 33 others

Description

is a sophisticated -based C&C framework employed by groups since 2023. It exploits across multiple environments to deliver advanced backdoors, targeting industries and Asian entities. The framework's versatility allows it to be used in various attack stages, from watering-hole control to lateral movement and C&C operations. Two campaigns, SHADOW-VOID-044 and SHADOW-EARTH-045, demonstrate coordinated threat group activity using . The framework is complemented by two modular backdoors, and , which extend its attack capabilities. 's design enables flexible deployment and execution across different environments, including browsers, MSHTA, WScript, Classic ASP, Node JS, and .NET.

External references